Spotify reportedly makes users’ private playlists public

According to the Bleeping Computer*, in what is shaping up to be a widespread privacy controversy, Spotify has come under scrutiny following allegations by users that the music streaming service made their private playlists public without their consent. This situation is reminiscent of a similar issue flagged back in March, raising concerns over a possible … More Spotify reportedly makes users’ private playlists public

USB drive malware attacks spiking again in first half of 2023

According to the Bleeping Computer*, what’s old is new again, with researchers seeing a threefold increase in malware distributed through USB drives in the first half of 2023. A new report by Mandiant outlines how two USB-delivered malware campaigns have been observed this year; one named ‘Sogu,’ attributed to a hacker group ‘TEMP.HEX,’ and another … More USB drive malware attacks spiking again in first half of 2023

The danger within: 5 steps you can take to combat insider threats

Some threats may be closer than you think. Are security risks that originate from your own trusted employees on your radar? It all began innocently enough when a Tesla employee received an invitation from a former associate to catch up over drinks. Several wining and dining sessions later, the old acquaintance made his real intentions … More The danger within: 5 steps you can take to combat insider threats

ESET Research Podcast: Finding the mythical BlackLotus bootkit

A story of how analysis of a supposed game cheat turned into a discovery of a powerful UEFI threat. Towards the end of 2022 an unknown threat actor boasted on an underground forum that they’d created a new and powerful UEFI bootkit called BlackLotus. Its most distinctive feature? It could bypass UEFI Secure Boot – a … More ESET Research Podcast: Finding the mythical BlackLotus bootkit